Oval Definition:oval:org.opensuse.security:def:68811
Revision Date:2021-06-23Version:1
Title:Security update for cryptctl (Important)
Description:

This update for cryptctl fixes the following issues:

Update to version 2.4:

- CVE-2019-18906: Client side password hashing was equivalent to clear text password storage (bsc#1186226) - First step to use plain text password instead of hashed password. - Move repository into the SUSE github organization - in RPC server, if client comes from localhost, remember its ipv4 localhost address instead of ipv6 address - tell a record to clear expired pending commands upon saving a command result; introduce pending commands RPC test case - avoid hard coding 127.0.0.1 in host ID of alive message test; let system administrator mount and unmount disks by issuing these two commands on key server.
Family:unixClass:patch
Status:Reference(s):1082318
1128828
1142614
1155094
1162825
1186226
CVE-2019-18348
CVE-2019-18906
CVE-2019-9674
CVE-2019-9893
SUSE-SU-2019:2517-1
SUSE-SU-2020:1339-1
SUSE-SU-2021:2136-1
Platform(s):SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for SAP Applications 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • libseccomp-2.4.1-3.3 is installed
  • OR libseccomp-tools-2.4.1-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for SAP Applications 15 SP1 is installed
  • AND cryptctl-2.4-4.5.1 is installed
  • BACK